Which of the following services can alert you to malware on an EC2 instance?
A. AWS GuardDuty
B. AWS Inspector
C. AWS Shield
D. AWS Web Application Firewall
A. GuardDuty looks for potentially malicious activity.
Inspector looks for vulnerabilities that may result in compromise.
Shield and Web Application Firewall protect applications from attack.
What does GuardDuty monitor?
What is the target of GuardDuty findings?
- The presence of malware on an EC2 instance (e.g. Trojan, Cryptocurrency)
What is Amazon Inspector?
Amazon Inspector is an agent-based service that looks for vulnerabilities on your EC2 instance.
What is Amazon Detective?
Amazon Detective takes information from VPC flow logs, CloudTrail, and GuardDuty and places this information into a graph database.
Detective is designed to help you correlate events and see how a given event affects particular resources.
What is Security Hub?
Security Hub collects security information from various AWS services, including Inspector, GuardDuty, and Macie. In addition, Security Hub assesses your account against AWS security best practices and the Payment Card Industry Data Security Standard (PCI DSS).
What is the difference between AWS Sheild Standard and Advanced?
How long does it take for Shield to mitigate DDoS attacks?
Can you directly encrypt a volume at rest?
No,
What is Macie?
Macie is a service that automatically locates and classifies your sensitive data in S3 buckets?
Can you encrypt an existing EFS system?
No, the only option to encrypt the data using KMS is to create a new EFS filesystem and copy the data to it.
What is the typical DDoS attacks?